Tapestry 360 Health, a Chicago-based network of community health centers, has notified patients that their protected health information was exposed in a data security incident at Aesto, LLC, a third-party company that provides healthcare data migration and archiving services for Tapestry 360 Health. The incident involved unauthorized copying of a limited amount of patient data stored on Aesto’s network.
Healthcare providers that rely on outside vendors to manage, migrate, or archive patient data have a responsibility to ensure those vendors adequately protect that information, since patients trust their providers with some of the most sensitive information about them. When a vendor’s security fails, the patients whose data was entrusted to that provider still deserve a clear explanation of what happened and meaningful protection going forward.
Tapestry 360 Health’s Data Breach Investigation
According to a notification letter sent to affected patients, Aesto experienced a network security incident on or about December 18, 2025 that impacted a limited portion of its Amazon Web Services infrastructure. Aesto, which provides healthcare data migration and archiving services on behalf of Tapestry 360 Health, launched an investigation with the help of outside cybersecurity professionals following discovery of the incident. After an extensive forensic investigation and manual document review, Aesto confirmed on May 26, 2026 that between approximately December 2, 2025 and December 18, 2025, an unauthorized actor copied a limited amount of protected health information belonging to Tapestry 360 Health patients that was stored on Aesto’s network.
This incident illustrates a growing risk area in healthcare data security: third-party vendors that handle data migration, archiving, or cloud storage on behalf of medical providers. Even when a healthcare provider itself maintains strong security practices, patient information can still be exposed if a vendor’s infrastructure is compromised, since the vendor often holds copies of the same sensitive records the provider maintains. Cloud infrastructure incidents, like the one described here involving Amazon Web Services systems, have become an increasingly common vector for healthcare data breaches as more providers and their vendors move records to cloud-based storage and archiving systems.
The roughly five-month gap between when the unauthorized copying reportedly occurred (December 2025) and when it was confirmed and disclosed to patients (May 2026) reflects how long a thorough forensic investigation and manual document review can take when an incident is discovered well after the fact, particularly when a third-party vendor and its healthcare-provider client must coordinate together on assessing exactly which patients and records were affected.
Aesto has stated it has no evidence that any of the exposed information has been misused for identity theft or fraud, but Tapestry 360 Health is offering patients a complimentary 24-month credit monitoring membership as a precaution. Given that the exposed information reportedly includes Social Security numbers and medical record numbers, in addition to names and dates of birth, affected patients face a real risk of identity theft and medical fraud and should take the protective steps outlined below.
When Did This Breach Occur?
Aesto detected a network security incident affecting a limited portion of its Amazon Web Services infrastructure on or about December 18, 2025. Following a forensic investigation, Aesto determined that unauthorized copying of patient data occurred between approximately December 2, 2025 and December 18, 2025. Aesto confirmed on May 26, 2026 that the copied information included protected health information belonging to Tapestry 360 Health patients, after which notification letters were sent to those affected.
What Information Was Breached?
According to the notification letter, the information potentially exposed includes each affected patient’s full name, date of birth, Social Security number, and medical record number. Tapestry 360 Health and Aesto have stated they have no evidence that this information has been misused for identity theft or financial fraud as of the date of the notice.
What You Can Do
If you received a notice from Tapestry 360 Health or Aesto, or believe you may have been affected, consider taking the following steps:
- Enroll in the complimentary 24-month Single Bureau Credit Monitoring membership offered in the notification letter within 90 days of the letter’s date.
- Request your free annual credit reports from Equifax, Experian, and TransUnion and review them for unfamiliar accounts or inquiries.
- Consider placing a fraud alert or security freeze on your credit files with the three major credit bureaus, given that Social Security numbers may have been exposed.
- Review your health insurance Explanation of Benefits statements for any services you do not recognize.
- Contact the dedicated response line provided in your notification letter if you have questions about your specific situation.
File a Data Breach Lawsuit Against Tapestry 360 Health
If you were notified that your personal or health information was involved in the Tapestry 360 Health/Aesto data breach, you may have legal options available to you. Healthcare providers and the vendors they rely on are expected to implement reasonable safeguards to protect patient data, and affected individuals may be entitled to compensation when those protections fail.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.